Splunk Search

How to recognize _indextime and _time as values in subseconds ?

sunrise
Contributor

Hi Splunkers,

I want to know how does it take for splunk to index the data in subseconds?
So I prepared the following configration file.

props.conf

[sampledata]
DATETIME_CONFIG = CURRENT

But in this time, Splunk add timestamps (in this case, system time) in seconds to each events.
I know that we cannot use "TIME_FORMAT" option together with "DATETIME_CONFIG = CURRENT".
And in default setting, index date (_indextime field) is also in second order.

How can we recognize there fields (_indextime and _time fileds) as values in subsecond order to calculate index time ?

Thank you for your help.


I updated my question below.

Splunk logs are recognized as subsecond timeformat events.
I used these logs to calculate the index time.
However, default "_indextime" fields don't have subsecond timeformat.
Can I change this definition to change to subsecond order event.

Tags (2)
0 Karma
1 Solution

sunrise
Contributor

You should use SplunkIt as a mesurement for the index and search performance.

SplunkIt | Utilities | Splunk Apps http://apps.splunk.com/app/749/

View solution in original post

0 Karma

sunrise
Contributor

You should use SplunkIt as a mesurement for the index and search performance.

SplunkIt | Utilities | Splunk Apps http://apps.splunk.com/app/749/

0 Karma

sunrise
Contributor

It seems to be better to use splunkit.
I'll try that.

0 Karma

sunrise
Contributor

I got something, so update the my question.
Splunk logs are recognized as subsecond timeformat event.
But "_indextime" field is not..
Can I change this timeformat to subsecond order ?

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...